Open iSCSI Project maintains an initiator implementation for iSCSI protocol support, a critical component for Linux systems accessing remote block-level storage over network fabrics. This narrowly scoped project presents a focused vulnerability profile centered on its single core product, with exposure typically rooted in the protocol parsing and session-management layers inherent to networked storage I/O. Current severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Iscsi Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17437HIGH An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, t | Dec 11, 2020 | 8.2 | 26 | NO | NO |
CVE-2020-13987HIGH An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_ | Dec 11, 2020 | 7.5 | 25 | NO | NO |
CVE-2017-17840HIGH An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect length | Dec 27, 2017 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Iscsi Project.
Media articles that mention a CVE ID that affects a product developed by Open Iscsi Project — matched by CVE ID, not by vendor name.